Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pull compliance data from external sources #406

Open
ab-smith opened this issue May 10, 2024 · 0 comments
Open

Pull compliance data from external sources #406

ab-smith opened this issue May 10, 2024 · 0 comments
Labels

Comments

@ab-smith
Copy link
Contributor

ab-smith commented May 10, 2024

Automation of compliance status and evidence collection can be tricky and misleading. Nevertheless, we can figure out a reasonable UX where this acts a "helper" and a plugin architecture and system to pull data and match specific applied controls.

If properly exposed on their API, we can experiment with the Wazuh to get a first level on the SIEM and XDR parts. Prowler seems like a reasonable option as well for some of the controls.

One of the challenges is that most tools will give only partial information and eventually overlap and conflict, so we need to stick to the "helper" approach and not set this on behalf of the auditor, given the bad previous experience on controls automation that the community reported.

@ab-smith ab-smith added the epic label May 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant